Subprocessors
SECRATO uses third party service providers
Last Updated: 30th July 2025
At Secrato, we use select third-party service providers (“subprocessors”) to help deliver and support our platform. Each subprocessor is subject to strict confidentiality obligations and operates under contractual agreements that align with the GDPR and our Data Processing Agreement (DPA).
We only share data with subprocessors as required to operate our services. No subprocessors have independent access to client data without our direction.
Current Subprocessors:
Subprocessor | Purpose | Location | Compliance Measures |
Amazon Web Services | Cloud hosting infrastructure | Frankfurt, EU | ISO 27001, GDPR |
SendGrid (Twilio) | Transactional email delivery | EU/US | DPA + Standard Clauses |
HubSpot | CRM & support communications | EU/US | DPA + SOC 2 |
Cloudflare | DDoS protection & CDN | Global (EU prioritized) | SCC, ISO 27001 |
We review all subprocessors for compliance posture, data handling practices, and security controls before onboarding.
For a signed DPA or more information, contact privacy@secrato.com.